Riverside County Office of Education
ent_5147528485966ad5d66ab1b0
Disclosures
3
State AG · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Riverside County Office of Education
- Normalized
- riverside county office of education— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- rcoe.us
Disclosure history (3)newest first
- 🐻California State AGas victim2023-12-15
Riverside County Office of Education notified parents of a data breach involving student information. The incident resulted from a global cybersecurity issue with Progress Software's MOVEit Transfer solution, where unauthorized actors exploited a previously unknown vulnerability. Between May 27 and May 31, 2023, an unauthorized third party obtained files containing student names, academic records, behavior information, enrollment data, special education details, disability codes, dates of birth, and demographic information. No Social Security numbers or financial data were involved. The district engaged cybersecurity experts, secured its MOVEit repository, reported to law enforcement, and offered one year of identity monitoring services to affected families.
- 🐻California State AGas victim2023-11-07
Riverside County Office of Education reported a data breach affecting its MOVEit Transfer file transfer appliance. The incident occurred on May 27, 2023, due to a vulnerability in the Progress Software MOVEit product (supply chain compromise). The breach potentially exposed personal information including names, addresses, and possibly Social Security numbers of students, parents, and employees. The organization is notifying affected individuals as required by California law.
- 🐻California State AGas victim2022-05-27
Illuminate Education, Inc., on behalf of the Riverside County Office of Education, disclosed a data breach involving unauthorized access to student databases between December 28, 2021, and January 8, 2022. The incident exposed student names and other personal information but explicitly excluded Social Security numbers and financial data. Illuminate rotated credentials, engaged forensic specialists, and offered 12 months of credit and identity monitoring to affected individuals.